IPAbuse Developers

cPanel / WHM Plugin

The IPAbuse cPanel plugin checks every incoming connection against the IPAbuse reputation API and blocks high-risk IPs via CSF (ConfigServer Security & Firewall) before they reach your server.

Requirements

  • cPanel & WHM 102 or later
  • CSF (ConfigServer Security & Firewall) installed
  • Root SSH access
  • IPAbuse API key
  • Outbound HTTPS to api.ipabuse.org

Install

cURL
# Download and run the installer as root
curl -fsSL https://downloads.ipabuse.org/plugins/cpanel/install.sh | bash

The installer registers a cPanel hook that fires on each incoming connection, installs the IPAbuse WHM plugin interface, and adds a cron job to keep the local blocklist cache warm.

Configure

Edit /etc/ipabuse/config.ini with your settings:

/etc/ipabuse/config.ini
[ipabuse]
api_key = YOUR_API_KEY
risk_threshold = 50
block_ttl = 3600
categories = SPAM,SSH_BRUTE_FORCE,WEB_ATTACK
log_file = /var/log/ipabuse/blocks.log
KeyDefaultDescription
api_key—Your IPAbuse API key (required)
risk_threshold50Block IPs with a reputation score below this value (0–100)
block_ttl3600Seconds to keep an IP in the local deny list before re-checking
categories(all)Comma-separated list of abuse categories to act on
log_file/var/log/ipabuse/blocks.logPath to the block log

Restart the service after editing:

cURL
service ipabuse-hook restart

Uninstall

cURL
curl -fsSL https://downloads.ipabuse.org/plugins/cpanel/uninstall.sh | bash

Next steps